PT-2026-33115 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-33220

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description The translation memory API exposes unintended endpoints that lack proper access control.
Recommendations Update to version 5.17. As a temporary workaround, ensure the CDN add-on remains disabled.

Fix

Information Disclosure

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33220
GHSA-MQPH-7H49-HQFM
PYSEC-2026-153

Affected Products

Weblate